Realst: New Rust-based Mac Malware Targets Crypto Wallets of Apple Users
A new information stealer dubbed ‘Realst’ is being used to target macOS users. Designed with multiple variants, the malware is ready to target Apple’s major operating system release, macOS 14 Sonoma.
First discovered by security researcher iamdeadlyz, the malware written in Rust is being distributed to both Windows and macOS users through multiple bogus blockchain games. Windows users are being infected with infostealers like RedLine Stealer and Mac users by Realst.
Using social media platforms, the attackers initially try to convince their targets to take part in a paid collaboration. Testing fake games like Brawl Earth, WildWorld, Dawnland, Destruction, Evolion, Pearl, Olymp of Reptiles, and SaintLegend, the attacker deploys the infostealer onto the targeted system to steal sensitive information and empty cryptocurrency wallets. ‘’Each version of the fake blockchain game is hosted on its own website complete with associated Twitter and Discord accounts,’’ stated SentinelOne report.
The malware targets Firefox, Chrome, Opera, Brave, and Vivaldi browsers but Apple Safari was the only exception among the analyzed browsers. The malware also has the capability to capture screenshots and download information from Telegram.
‘’Most variants attempt to grab the user’s password via osascript and AppleScript spoofing,’’ Realst also performs a basic check to confirm the host machine is a real or virtual one ‘’via sysctl -n hw.model,’’ the report read.
During the investigation, it was also found that ‘XProtect’ Apple’s malware blocking service was unable to prevent the execution of this malware. Furthermore, SentinelOne analyzed 59 malicious Mach-O samples and found distinct differences among the identified 16 variants of the malware.
‘’The number of Realst samples and their variation shows that the threat actor has invested serious effort in order to target macOS users for data and crypto wallet theft,’’ SentinelOne said. ‘’Given the current popular interest in blockchain games, which promise users the reward of making money while gaming, users and security teams are urged to treat solicitations to download and run such games with extreme caution.’’
Moreover, the growing popularity of infostealers and their availability as malware-as-a-service offering should also be taken into consideration while deploying security solutions, especially with the increasing availability of stolen data, packaged and sold on dark web and Telegram platforms.
Leave a Comment
Cancel